Legal
Privacy Policy
Pocketly ("we", "our", or "us") is a personal expense-tracking app. This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information. By using Pocketly you agree to the practices described here.
1. Information We Collect
1a. Data stored only on your device
- Expense records – amounts, dates, categories, merchants, and notes you enter.
- Categories and budgets – custom labels and limits you create.
- App preferences – currency, language, theme, and notification settings.
This data is stored in a local SQLite database on your device and is never transmitted to us or any third party.
1b. Data transmitted off-device
| Data | Purpose | Recipient |
|---|---|---|
| Anonymous device ID (UUID) | Enforce free scan quota (10/month) and show how many scans are left; link subscription entitlement to device | Our Vercel backend; RevenueCat |
| Two currency codes, e.g. USD and EUR (only when an amount is converted between currencies) | Look up the day's exchange rate; our backend fetches it from HexaRate or the European Central Bank's reference rates (Frankfurter), so those providers never see your device | Our Vercel backend |
| Receipt images (when you use cloud OCR scan) | Extract merchant, amount, and date from a receipt photo using AI vision | Our Vercel backend → Anthropic Claude API |
| Purchase / subscription information | Validate and manage in-app subscriptions (weekly, monthly, yearly) | RevenueCat; Apple App Store / Google Play |
| Anonymous usage events (screens viewed, feature-usage flags — never amounts, merchants, notes, or any financial values) | Understand which features are used so we can improve the app; optional — switch off anytime in Settings → Data & Privacy | PostHog (hosted in the EU) |
| Push token + anonymous device ID (only after you allow notifications) | Deliver push notifications such as feature news and subscription notices | OneSignal |
| Encrypted backup file (optional cloud sync) | Back up your data to your own cloud account; encrypted on your device before upload — we never see its contents and it never touches our servers | Your iCloud / Google Drive |
2. How We Use Your Information
- Process receipt images to automatically fill in expense details (cloud OCR feature).
- Track how many receipt scans a device has performed in a billing period to enforce the free-tier quota.
- Verify active subscription entitlements so premium features unlock correctly.
- Measure anonymous feature usage (e.g. which screens are opened) to guide improvements — with no financial values attached, and only while the analytics toggle is on.
- Send optional push notifications (e.g. product news or subscription status messages) if you have allowed notifications.
- We do not use your data for advertising, profiling, or selling to third parties, and we do not track you across other companies' apps or websites.
3. Receipt Images & OCR Processing
When you tap "Scan Receipt" using the cloud OCR feature, the image is compressed and
sent over HTTPS to our backend proxy hosted on Vercel
(pocketly-proxy.vercel.app). The proxy forwards it to Anthropic's Claude API
for text extraction. Receipt images are processed in real-time and are not stored
on our servers or Anthropic's servers after processing. The extracted data
(merchant name, total amount, date) is returned to your device and saved locally.
The on-device OCR feature (available on supported devices) processes images entirely on your device and never sends any data off-device.
4. Device Identifier
Pocketly generates a random UUID the first time the app is installed and stores it securely on your device using the OS secure keystore. This ID is anonymous — it is not linked to your name, email, or any other personally identifiable information. It is used solely to count scan usage per device, to show you how many scans you have left, and to associate your RevenueCat subscription entitlement with your device.
5. Anonymous Usage Analytics
Pocketly collects anonymous usage statistics through PostHog (hosted in the European Union) to understand which features are used and to improve the app. Events carry a random analytics ID and simple flags such as "an expense was added" — they never include amounts, merchant names, notes, account or category names, or any other financial content. The analytics ID is random, is not linked to your name or email, and is not an advertising identifier: Pocketly does not access the advertising ID (IDFA/AAID) and does not track you across other apps or websites.
Your choice: analytics can be switched off at any time in Settings → Data & Privacy → "Share anonymous usage data". The opt-out takes effect immediately and persists across app restarts. RevenueCat also forwards anonymous subscription events (e.g. "trial started") to PostHog so we can understand subscriptions without collecting anything new. We process this anonymous, opt-out measurement on the basis of our legitimate interest in improving the app.
6. Push Notifications
If you allow notifications, Pocketly registers your device with OneSignal, our push delivery provider. OneSignal receives a push token and the same anonymous device ID described above — nothing else. We use push for messages such as feature announcements and subscription-related notices (for example, a free trial ending). Most reminders in Pocketly (bills, budgets, income) are local notifications scheduled on your device and involve no server at all. You can stop push at any time by disabling notifications for Pocketly in your system settings, and you can ask us to delete the associated device record (see "Your Rights").
7. Third-Party Services
| Service | Purpose | Privacy Policy |
|---|---|---|
| RevenueCat | In-app subscription management | revenuecat.com/privacy |
| Anthropic (Claude API) | AI-powered receipt text extraction | anthropic.com/privacy |
| PostHog (EU Cloud) | Anonymous product analytics | posthog.com/privacy |
| OneSignal | Push notification delivery | onesignal.com/privacy_policy |
| Vercel | Hosting for our backend proxy | vercel.com/legal/privacy-policy |
| Apple App Store / Google Play | App distribution and payment processing | Apple & Google privacy policies |
8. Permissions
| Permission | Why it's needed |
|---|---|
| Camera | Take photos of receipts for OCR scanning |
| Photo Library / Storage | Pick existing receipt images from your gallery |
| Biometrics / Fingerprint | Optional app lock using Face ID or fingerprint — processed entirely on-device |
| Notifications | Optional local reminders (bills, budgets, income) and, if enabled, remote push (feature news, subscription notices) |
| Internet | Cloud OCR, subscription validation, and restore purchases |
9. Data Retention
- On-device data: Retained until you delete the app or manually clear data.
- Receipt images: Not retained on our servers after OCR processing.
- Scan usage counters: Stored in our backend (keyed by anonymous device ID) and reset each billing period.
- Subscription records: Managed by RevenueCat; subject to their retention policy.
- Analytics events: Held by PostHog in our EU project, keyed only by the random analytics ID; deleted on request.
- Push device records: Held by OneSignal while notifications are enabled; removed when you unsubscribe or on request.
- Cloud backups: Stored in your own iCloud / Google Drive under your account's control; delete them there at any time.
10. Children's Privacy
Pocketly is not directed to children under 13 (or the applicable age in your jurisdiction). We do not knowingly collect personal information from children.
11. Your Rights
Because most data is stored exclusively on your device, you can delete it at any time by clearing app data or uninstalling the app. You can switch off usage analytics in Settings → Data & Privacy whenever you like. To have server-side records deleted — the anonymous analytics profile (PostHog), the push device record (OneSignal), or the subscription record (RevenueCat) — email us and we will remove them; they are keyed only by the anonymous IDs described above. EU/UK users additionally have the rights of access, rectification, erasure, restriction, and objection under the GDPR. For any other requests or questions, contact us at the email below.
12. Security
All data transmitted to our servers is encrypted in transit using TLS. Sensitive local data (such as your device ID) is stored in the OS secure keystore (iOS Keychain / Android Keystore). We do not store financial data on any server.
13. Changes to This Policy
We may update this policy from time to time. The "Last updated" date at the top of this page will reflect any changes. Continued use of Pocketly after an update constitutes acceptance of the revised policy.
14. This Website
This website (pocketly.flourixlab.com) uses PostHog, hosted in the European Union, to count visits and see which parts of the site are used. It records the pages you view, the links and buttons you click, the page that referred you, your browser, operating system, and screen size, how quickly pages load, and any errors in the site's scripts. It sets no cookies and stores nothing on your device. To tell visits apart, PostHog computes a one-way hash of your IP address and browser details on its servers, using a value that changes every day; your IP address itself is not stored. We do not record sessions on the website.
The website is served by Cloudflare and loads its fonts from Google Fonts; like any web server, both receive your IP address when delivering those files. Messages sent through the help form go by email to our support inbox and are not sent to PostHog.
15. Contact Us
If you have questions or concerns about this privacy policy, please contact us at:
ahmedclubust@gmail.com